Chapter 10 Configuring the Sensor Using the CLI
Sensor Configuration Tasks
10-46
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Step 4
Enter tune micro-engines submode:
sensor(config-vsc)# tune-micro-engines
Step 5
Type the name of the signature engine that you want to tune.
Note
You can view a list of all signature engines by typing a question mark (?)
at the
sensor(config-vsc-virtualSensor)#
prompt.
For example, to tune a simple UDP packet alarm, type the following command:
sensor(config-vsc-virtualSensor)# ATOMIC.UDP
Step 6
View the signature settings:
sensor(config-vsc-virtualSensor-ATO)# show settings
A summary of the signatures and settings is displayed.
sensor(config-vsc-virtualSensor-ATO)# show settings
ATOMIC.UDP
-----------------------------------------------
version: 4.0 <protected>
signatures (min: 0, max: 1000, current: 13)
-----------------------------------------------
SIGID: 9019 <protected>
SubSig: 0 <protected>
AlarmDelayTimer:
AlarmInterval:
AlarmSeverity: informational <defaulted>
AlarmThrottle: FireOnce <defaulted>
AlarmTraits:
CapturePacket: False <defaulted>
ChokeThreshold: 100 <defaulted>
DstIpAddr:
DstIpMask:
DstPort: 2140 <defaulted>
Enabled: False <defaulted>
EventAction:
FlipAddr:
MaxInspectLength:
MaxTTL:
MinHits:
MinUDPLength:
Protocol: UDP <defaulted>
ResetAfterIdle: 15 <defaulted>
ShortUDPLength:
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...